Skip to content

Security: TheMayaNutCompany/mayanut.github.io

Security

SECURITY.md

Security Policy

Supported Versions

Security updates are currently provided for the latest version of this project only.

Version Supported
main ✔ Yes
Older versions ❌ No

Reporting a Vulnerability

If you discover a security vulnerability in the code, website, or related project assets, please do not open a public issue.

Instead, report it privately to:

📧 info@mayanut.com
Subject: Security Vulnerability Report

Please include, where possible:

  • a clear description of the issue
  • steps to reproduce it
  • affected page, file, or feature
  • browser and device information
  • screenshots or supporting details, if helpful

We will acknowledge your message within 5 business days.


Responsible Disclosure Guidelines

Please:

  • do not publicly disclose the issue before it has been reviewed and addressed
  • do not perform testing that harms availability, stability, or access to the site
  • do not attempt to access private, restricted, or non-public data
  • do not use automated scanning or traffic patterns that overload the site or hosting environment
  • do not modify, delete, or exfiltrate data during testing

We will aim to:

  • review and validate reported issues
  • respond in a reasonable timeframe
  • keep communication as clear as possible during remediation
  • provide acknowledgment or credit, if appropriate and desired

Scope

This policy applies to:

  • https://mayanut.com
  • this GitHub repository
  • public-facing web assets maintained as part of The MayaNut Company website project

Examples may include:

  • HTML, CSS, and JavaScript in this repository
  • static assets and configuration files
  • page behavior, routing, metadata, and client-side UI interactions

Out of scope:

  • third-party infrastructure not controlled by this project, including GitHub Pages platform infrastructure
  • social media accounts or third-party services
  • physical security matters
  • general SEO, content, styling, or usability issues that do not create a security risk

Trademark and Brand Notice

Security reporting does not grant any right to use MayaNut™, Maya Nut™, or any branding associated with The MayaNut Company.

Any reference to names, marks, branding, or associated materials remains subject to applicable trademark and brand restrictions.


Good-Faith Research

We appreciate responsible, good-faith efforts to identify and report legitimate security concerns.

Please act carefully, minimize impact, and avoid actions that could disrupt the site, hosting environment, or related project assets.


Thank You

We appreciate anyone who helps improve the security, stability, and resilience of The MayaNut Company’s online presence.

There aren't any published security advisories